Skip to content
Log inRegister

EN 18286 Has Been Published. The Presumption of Conformity Has Not.

Dr. Abeer Alshammari · Published 9/16/2026

IntermediateProfessionalsCISOsExecutives

Two European standards for artificial intelligence reached milestones this year, and the gap between what they achieved and what most compliance plans assume they achieved is where the risk now sits.

On 18 March 2026, EN ISO/IEC 42001:2026 was published as the European adoption of ISO/IEC 42001:2023, the international standard for AI management systems. Over the summer, EN 18286 — "Artificial Intelligence — Quality Management System for EU AI Act Regulatory Purposes" — completed its formal approval and moved to publication, with national adoptions following. Both are real milestones. Neither, as things stand, produces a presumption of conformity with the AI Act.

What Article 40 actually says

Article 40(1) of Regulation (EU) 2024/1689 grants the presumption of conformity to high-risk AI systems and general-purpose AI models that conform to harmonised standards "the references of which have been published in the Official Journal of the European Union." The legal effect does not come from the technical quality of the document, from its EN prefix, or from a certificate on a wall. It comes from a procedural chain: a Commission standardisation request, development by the European standardisation organisations, Commission scrutiny, and finally citation in the Official Journal.

That last step has not yet happened for any AI Act standard. Until it does, Article 40 is inert, and a provider demonstrates conformity the hard way — requirement by requirement, from first principles, carrying the full evidentiary burden if a market surveillance authority asks.

The category error at the centre of many programmes

The more expensive mistake is not the timing. It is treating ISO/IEC 42001 certification as a substitute for the Article 17 quality management system. These are different instruments answering different questions.

ISO/IEC 42001 certifies an organisation. It establishes an AI management system: governance, roles, risk processes, documentation discipline across whatever AI the organisation builds or uses. It is voluntary, certifiable under accreditation, and — with ISO/IEC 42006:2025 now setting requirements for the bodies that certify against it — increasingly credible as an assurance signal.

Article 17 regulates a product. It applies per high-risk AI system placed on the EU market, and it enumerates thirteen elements the quality management system must contain in writing: a regulatory compliance strategy including conformity assessment and a procedure for managing modifications; design control and verification; development, quality control and quality assurance procedures; examination, test and validation procedures with stated frequency; technical specifications applied; data governance covering acquisition, labelling, storage, aggregation and retention; the Article 9 risk management system; post-market monitoring under Article 72; serious incident reporting under Article 73; communication with competent authorities; record-keeping; resource and supply chain management; and a named accountability framework.

ISO/IEC 42001 was not written against that list. It predates the final AI Act text, was not developed in response to the Commission's standardisation request, and the European AI Office signalled as early as 2024 that it was not fully aligned. The recurring gaps are consistent across independent analyses: no per-system regulatory compliance strategy mapping each requirement to evidence; no predetermined change-management procedure of the kind Article 17(a) demands for systems that continue to learn; no codification of the Article 73 incident timelines, which run to two days for incidents disrupting critical infrastructure, ten days where a death has occurred, and fifteen days for other serious incidents; supply chain provisions that are general rather than tied to specific AI suppliers and data sources; and no structured fundamental rights assessment of the kind the Act assumes.

Why this is not an argument against certification

None of this makes ISO/IEC 42001 a poor investment. EN 18286 includes an annex mapping its requirements to ISO/IEC 42001 Annex A controls, and another mapping to ISO 9001, precisely so that organisations with existing management systems can extend rather than rebuild. An organisation that already runs a disciplined AI management system will implement Article 17 faster and more cheaply than one starting from a blank page. The error is not adopting 42001; it is stopping there and calling it compliance.

What the Digital Omnibus does to the clock

The Digital Omnibus proposal of 19 November 2025, on which the Council reached a general approach on 13 March 2026, is widely described as a delay. It is more precisely a conditional trigger: high-risk obligations become applicable a set period after the Commission confirms that supporting standards are available — six months for Annex III systems, twelve for Annex I — with hard backstops of 2 December 2027 and 2 August 2028 regardless.

Read that carefully. Standardisation progress no longer only determines whether you get legal cover; it determines when your obligations start. EN 18286's publication and eventual citation are not procedural trivia happening to someone else. They are the events that start your implementation clock, and the backstop dates apply whether or not the standards arrive.

What to do between now and citation

Build to Article 17, not to a standard. The thirteen elements are the binding reference whatever happens in the standardisation process; the standard is a route to demonstrating them, not a replacement for them. Use the published EN 18286 clause structure as the scaffold for a gap assessment now, accepting that you may re-baseline once the text is cited.

Start with the accountability framework under Article 17(m), because assigning named owners across thirteen elements is the slowest organisational change to land. Extend procurement language to cover Article 17(l) — foundation model providers and data suppliers sit inside your quality management system whether or not your contracts say so. And track two distinct events: EN publication, which has largely happened, and Official Journal citation, which has not.

Governance maturity is not the same thing as legal certainty. In 2026, organisations serious about AI Act readiness will hold both — and will know precisely which one they currently have.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights